Selective Network Traffic Mirroring via Bitwise Granular Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, including firewalls and anti-virus software, have limited monitoring and reaction capabilities, failing to detect new types of attacks and prevent their propagation within local area networks, and are inefficient due to non-deterministic performance and high costs associated with advanced hardware components.

Innovation Solution

An apparatus that facilitates selective mirroring of network traffic through processing based on provisioned rules and policies, using a data processor to generate mirrored data with bitwise granularity across headers and payloads, enabling flexible and advanced network security and monitoring features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If advanced security systems use off-the-shelf computer system components (CPUs, memory, operating systems), then the device complexity is reduced and cost is lowered, but the monitoring and detection capabilities are insufficient and performance is non-deterministic

Engineering Contradiction:
Improvesystem complexityVSAvoidperformance determinism
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the network security system into multiple specialized functional modules: a network processor for high-speed packet processing, content addressable memory for signature matching, and a rule engine for policy-based traffic management. This segmentation allows each component to be optimized for its specific function, achieving deterministic performance while maintaining reasonable complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a specialized network processor as an intermediary between the standard CPU and the network traffic. This intermediary handles the computationally intensive tasks of packet inspection, signature matching, and traffic filtering, freeing the standard CPU from real-time processing demands and enabling deterministic security operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If hardware architectures are not customized for network security applications, then the ease of manufacture is improved and cost is reduced, but the performance is non-deterministic and validation is difficult

Engineering Contradiction:
Improvemanufacturing easeVSAvoidprocessing speed
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent designs a network security apparatus that combines multiple functions into a single platform: intrusion detection, traffic filtering, packet inspection, and logging. By making the system universal and multi-functional, it achieves high processing speeds for various security tasks without requiring separate specialized hardware for each function, thus maintaining manufacturing efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs content addressable memory (CAM) with configurable parameters for signature matching and pattern recognition. By allowing dynamic configuration of search parameters and matching criteria, the system achieves high-speed processing adaptable to different security requirements while using standard hardware components that are easy to manufacture.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If memory hierarchy, caches, or complex queuing structures are added to support high bandwidth and low latency, then the productivity is improved, but the device complexity increases

Engineering Contradiction:
Improvebandwidth handlingVSAvoidarchitecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the complex memory hierarchy and caching functions into dedicated network processor components that are optimized for packet processing. Rather than adding complex memory structures to a general-purpose system, the extraction principle is applied by using specialized hardware blocks within the network processor that handle high-speed packet buffering and caching, thus achieving high bandwidth without significantly increasing overall system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If firewall filters traffic based on packet header only, then the ease of operation is improved and processing speed is maintained, but the detection capability for deep packet contents is lost

Engineering Contradiction:
Improveoperation simplicityVSAvoidattack detection capability
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a dynamic traffic inspection system that adapts its inspection depth based on traffic characteristics and security policies. The rule engine dynamically determines whether to perform shallow header-only filtering or deep packet inspection based on configured policies, threat levels, and resource availability. This dynamic approach maintains operational simplicity while enhancing detection capability when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different inspection depths to different traffic flows based on local quality requirements. Critical traffic types (e.g., known malicious patterns, high-risk ports) receive deep packet inspection with full payload analysis, while normal traffic receives faster header-only filtering. This local differentiation maintains overall system simplicity while providing enhanced detection where necessary.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7882554B2Apparatus and method for selective mirroring
Publication Date: 2011.02.01 CPACKET NETWORKS
  • US7882554B2 patent drawing
  • US7882554B2 patent drawing
  • US7882554B2 patent drawing

AI summary

An apparatus is described that facilitates selective mirroring through processing of network traffic in accordance with provisioned rules and policies. The apparatus includes a port included in a set of at least one port, wherein each port in the set receives input traffic, a data processor that processes input data from the set of at least one port to generate mirrored data, based on rules with bitwise granularity across a header and a payload of the input data, and a mirror port selectable from the set of at least one port that transmits output traffic corresponding to the mirrored data. Advantageously, the apparatus provides an architectural framework well suited to a low cost, high speed, robust implementation of selective mirroring that enables flexible, advanced network security and monitoring features and network traffic analysis.